Download your favorite Linux distribution at LQ ISO.
Go Back > Forums > Linux Forums > Linux - Software
User Name
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.


  Search this Thread
Old 10-17-2008, 11:38 AM   #1
LQ Newbie
Registered: May 2008
Location: USA
Distribution: Ubuntu 8.10 Intrepid Ibex
Posts: 4

Rep: Reputation: 0
Question Using GrokEVT to convert Windows Server 2003 Logs to CSV - Registry Issues

I am trying to set up GrokEVT so that I can generate .csv files of our Windows server logs here at the office. I like the control a .csv gives me compared to the Windows Event Viewer.

I also like that GrokEVT will glean all information in regards to the event logs including pulling from DLLs and the registry instead of just the .evt files.

I have installed and configured GrokEVT for my system just as the man page instructions say, but when it comes time for me to run grokevt-builddb (build a database for event log conversion) on my configuration file, I receive the following error:
root@ubuntu:/usr/local/etc/grokevt/systems# grokevt-builddb 22c /var/db/grokevt/22c
WARNING: reglookup reported: ERROR: Couldn't open registry file: /media/22C/WINDOWS/system32/config/system
ERROR: Could not automatically determine CONTROL_SET_ID
The first message in this case is most certainly because the system file is in use. Servers are always supposed to be running, and I doubt a Windows server would ever unlock this registry file that reglookup (a dependency of GrokEVT) needs to read.

This theory is further proven by the output of the cp command, saying the text file is in use:
cp: cannot open `/media/20C/WINDOWS/system32/config/system' for reading: Text file busy
I have mounted the local drives of all of our servers via Samba. Has anyone else experienced these difficulties with building a database for log file conversion, or accessing any registry files while using GrokEVT/reglookup?

I have, of course, Googled to no avail (frighteningly few search results), as well as checked permissions on the files and parent directories. It is clear that the file is locked by Windows and I need to find some way to circumvent this lock through the Samba file share so reglookup can read the file.

Any help would be greatly appreciated.

Old 12-11-2009, 08:14 AM   #2
Registered: Apr 2009
Location: Sydney, Australia
Distribution: Ubuntus, Fedora, openSUSE, and Vector Lite 6.0
Posts: 46

Rep: Reputation: 16
did you ever get this resolved? I think this should be bumped to the application thread or the security thread.

Anyway I am having similar issues while trying to run grokevt against W2K event logs. I am doing a forensic investigation and this is the error I get when I run
sudo grokevt-builddb /usr/local/etc/grokevt/systems/TBG1 ./db/grokevt/TBG1/
ERROR: [Errno 2] No such file or directory: '/media/try_tbg1/winnt/system32/config/appevent.evt'
ERROR: could not copy all log files.
When I try to cd to /media/try_tbg1/winnt I notice that I cannot cd to it because winnt is "WINNT" and the mount is still case sensitive.

The man for grokevt specifies that you have to mount your images with the -o posix=0 option. I have tried the following but it seems that I am still getting a case sensitive mount:
sudo mount -t ntfs -o posix=0 /dev/loop0 /media/try_tbg1/
I had a look at the man for mount and is says that -o posix=0 is depricated for -t ntfs.

Does anybody know if there is another way to mount an image file, it is a loop device actually as I have the entire drive imaged, to make sure that it is mounted case-insensitive?
Old 12-16-2009, 11:14 AM   #3
LQ Guru
Registered: Dec 2006
Location: underground
Distribution: Slackware64
Posts: 7,594

Rep: Reputation: 550Reputation: 550Reputation: 550Reputation: 550Reputation: 550Reputation: 550
Since this thread is not directly security related, despite the potential use of the software in a security context, I've moved it to /Software, since it appears to be more of a "..this software is giving me trouble.." question.



locked, logs, server, windows

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
import users from Windows LDAP server to Windows 2003 server kpachopoulos General 2 11-26-2008 07:23 PM
Convert into CSV file say_hi_ravi Programming 4 07-17-2008 04:25 AM
convert excel to csv and html thelonius Programming 3 03-28-2007 12:16 PM
Script to convert csv 2 xls or odt xowl Linux - Software 1 01-16-2007 10:06 PM
Samba 3.02 & Windows 2003 issues Chrisb009 Linux - Networking 2 08-11-2004 07:31 AM

All times are GMT -5. The time now is 10:19 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration